Skip to main content

Command Palette

Search for a command to run...

How DNS Resolution Works

Published
•9 min read•View as Markdown
How DNS Resolution Works
A
Web Developer

The Domain Name System, or DNS for short, is often referred to as the phone book of the internet.

Have you ever thought about what really happens when you type google.com into your browser and a website opens almost instantly? It may feel like magic, but there’s a smart system working quietly in the background called DNS (Domain Name System).

DNS helps the internet understand what website you want to visit. Since computers don’t understand website names, DNS converts easy names like google.com into special numbers called IP addresses. These numbers tell your browser exactly where the website is located, allowing it to load the page for you in just seconds.

What Is DNS and Why Is It Important?

DNS (Domain Name System) is a system that converts human-friendly domain names into machine-readable IP addresses. Without DNS, you would have to remember numbers instead of names for every website you visit.

How DNS Resolution Works (Step-by-Step)

Let’s break down DNS resolution into simple steps.

Step 1: User Enters a Domain Name

When you type any domain, for example, ‘amazon.com’ into your browser, it sends a request to a DNS resolver to find the website’s IP address.

Step 2: DNS Recursive Resolver Checks Cache

The resolver first checks its cache to see if it already has the IP address stored. If found, it returns the result immediately.

**Step 3: Query to Root Name Server
**If the IP isn’t cached, the resolver contacts a root name server. The root server doesn’t know the exact IP, but directs the resolver to the correct TLD server (e.g., .com).

Step 4: Query to TLD Name Server

The resolver then reaches out to the TLD server for the domain extension. The .com TLD server helps locate the authoritative DNS server for ‘amazon.com’.

Step 5: Query to Authoritative DNS Server

The authoritative server holds the domain’s DNS records and provides the correct IP address for the website.

Step 6: Returning the Final IP Address to the Browser

The resolver sends the final IP address back to your browser.

Step 7: Browser Connects to the Web Server

With the IP address, your browser connects to the website’s server and loads the webpage for you.

Real Life Example

🌍 Real-Life Example: Finding a Friend’s House

Imagine you want to visit your friend Amazon, but you only know their name, not their house address.

🧑 Step 1: You Ask for the Name (User Enters Domain)

You say:

“I want to go to Amazon’s house.”

👉 This is like typing amazon.com in your browser.


📒 Step 2: Ask Your Phone Contacts (DNS Cache Check)

First, you check:

“Do I already have Amazon’s address saved in my phone?”

  • If YES → You go directly.

  • If NO → You ask others.

👉 This is the DNS resolver checking its cache.


🌍 Step 3: Ask the City Information Office (Root DNS Server)

You go to the main city office and ask:

“Where can I find someone named Amazon?”

They reply:

“Amazon lives in the .com area. Ask the .com office.”

👉 Root server doesn’t know the address, but guides you.


🏢 Step 4: Ask the Area Office (.com TLD Server)

Now you go to the .com area office and ask:

“Where exactly is Amazon in this area?”

They reply:

“Ask Amazon’s own building manager.”

👉 This is the TLD server pointing to the authoritative server.


🏠 Step 5: Ask the Building Manager (Authoritative DNS Server)

You ask Amazon’s building manager:

“What is Amazon’s exact house number?”

They answer:

“Here is the exact address: IP Address.”

👉 This server has the final, correct information.


📲 Step 6: Address Given Back to You (IP Returned)

The address is sent back to you:

“Here’s where Amazon lives.”

👉 DNS resolver sends the IP address to your browser.


🚶 Step 7: You Visit the House (Browser Connects)

Now that you know the address:

You go straight to Amazon’s house and meet them.

👉 Browser connects to the web server and loads the website.


DNS Caching Explained

DNS caching helps speed up the process of finding a website’s IP address by storing previous lookup results temporarily.

Common DNS Issues and Errors

DNS_PROBE_FINISHED_NXDOMAIN

This error appears when the domain cannot be found, usually because the domain doesn’t exist, or there’s a DNS misconfiguration.

DNS Server Not Responding
This occurs when the DNS server you are using is down, unavailable, or unable to process requests.

**Slow DNS Resolution
**Happens when DNS servers are slow, overloaded, or the request has to travel through multiple distant servers, causing delays in loading websites.

How to Improve DNS Performance

Use Faster DNS Providers

Switch to trusted and high-speed DNS providers, like Cloudflare (1.1.1.1), Google DNS (8.8.8.8), or OpenDNS to reduce lookup time and improve browsing speed.

**DNS Load Balancing
**Balances traffic across multiple DNS servers to increase reliability and ensure the system stays available even during high traffic.

Use Anycast DNS

Distributes DNS servers across the globe so users connect to the nearest server, resulting in faster response times.

DNSSEC for Security

Adds a layer of security by preventing DNS spoofing and ensuring that DNS responses are authentic.

The Role of DNS in the Internet World

📱 Phone Contacts Example

  • You save a name like “Mom” in your phone.

  • When you tap Mom, your phone automatically uses the number stored behind the name.

  • You don’t need to remember the phone number every time.

👉 DNS works the same way

  • You type google.com

  • DNS finds the IP address (like 142.250.192.14)

  • Your browser connects to the website instantly

Key Components of DNS

For DNS to work efficiently, several components interact with each other, during the resolution process.

1) DNS Client (Resolver)

A DNS resolver is the first point of contact when your device needs to find the IP address of a website. It is usually provided by your ISP, or a public DNS service like Google (8.8.8.8) or Cloudflare (1.1.1.1). Its job is to receive your DNS request and start the process of finding the correct IP address for the domain you entered.

**2) Root Name Servers
**Root name servers are at top level in DNS hierarchy. They don’t store website IP addresses, but act as a guide. When the resolver doesn’t know where to find the domain, the root server directs it to the correct Top-Level Domain (TLD) server (like .com, .net, or .org).

3) TLD Name Servers

TLD servers manage information for specific domain extensions such as .com, .net, .org, .in, etc. When contacted, they don’t give the final IP, but point the resolver to the correct authoritative name server responsible for the domain.

4) Authoritative Name Servers

These servers hold the actual DNS records of a domain. They provide the final answer, the correct IP address of the website, which is then sent back to the user’s browser to load the site.

**5) DNS Records and Their Types:
**DNS records are like instructions stored on authoritative servers that tell the DNS how a domain should function. The key record types include:

  • A Record: This record links a domain name to its IPv4 address (e.g., 192.168.1.1). It tells browsers, which server to connect to when someone types your domain.

  • AAAA Record: Similar to the A record, but it maps a domain to an IPv6 address (e.g., 2001:db8::1). It supports the newer, longer IP format.

  • CNAME Record: A CNAME (Canonical Name) record points one domain name to another domain name. It’s often used for subdomains, for example, pointing blog.example.com to example.com.

  • MX Record: The MX (Mail Exchange) record specifies which mail server should handle emails for a domain. Without it, email services won’t know where to deliver your messages.

  • TXT Record: A TXT record stores text-based information. It’s commonly used for verification and security, such as SPF, DKIM, and Google site ownership verification.

  • NS Record: This record shows, which name servers are authoritative for a domain, meaning they hold the actual DNS records and answer DNS queries for that domain.

    What is the dig command and when it is used

    The dig command, short for domain information groper, is a powerful network tool for querying domain name system (DNS) servers. It helps diagnose and resolve DNS-related problems, essential for maintaining network stability and performance.

  • Syntax

    The basic syntax of the dig command is as follows

  •   dig [server] [name] [type]
    

Here’s an explanation of each argument:

  • [server] (optional). The IP address or hostname of the DNS server to query. dig will use the DNS servers listed in /etc/resolv.conf if omitted.

  • [name]. The domain name to query. This is the DNS resource record about which you want information.

  • [type] (optional). The DNS record type to query, including A, MX, and NS. dig will query an A record if no type is specified by default.

For instance, to query an A record for example.com, you can run:

dig example.com

What is the dig command used for?

The dig command is used to query DNS name servers. It retrieves DNS information about numerous records, such as A, MX, and NS, helping diagnose and resolve network-related problems.

Understanding dig . NS and root name servers

The NS records identify the name servers, responsible for your DNS zone.

  • dig → Tool to ask DNS questions

  • dig NS → Find who manages a domain

What is dig NS?

NS = Name Server

When you run:

dig google.com NS

You are asking:

❓ “Who is responsible for telling the address of google.com?”

In simple words:

  • dig NS tells you which servers manage a domain

  • These servers know where the website lives (its IP)


Real-life example 🏠

  • Domain name → google.com

  • Name servers → The caretakers of the domain

  • They know:

    • Website IP

    • Email records

    • Other DNS details

So:

dig google.com NS

\=
“Show me the caretakers of google.com”

Explain how DNS resolution happens in layers: root → TLD → authoritative

DNS is not one big database. It’s hierarchical:

  1. Root name servers (.)

  2. TLD name servers (.com, .org, .in)

  3. Authoritative name servers (google.com)

Each layer only knows where to go next

4️⃣ dig . NS → Root name servers

Command

dig . NS

What it means

  • . = root of DNS

  • Asking:
    “Who manages the root of the internet?”

Role of recursive resolver (hidden hero)

You never talk to root/TLD servers directly.

  • Your system uses a recursive resolver

  • Resolver:

    • Walks the hierarchy

    • Caches answers

    • Reduces internet load

Example resolvers:

  • ISP DNS

  • Google DNS 8.8.8.8

  • Cloudflare 1.1.1.1

📌 Caching is why websites load fast

9️⃣ Connecting this to real browser requests

When you type:

https://google.com

Browser needs:

  1. IP address → DNS
  1. TCP connection → IP

  2. TLS handshake → HTTPS

  3. HTTP request → page load

👉 DNS is always the first step

If DNS fails → nothing works

🔟 One-screen mental model (interview ready)

dig . NS
→ Root servers (start point)

dig com NS
→ TLD servers (.com owners)

dig google.com NS
→ Authoritative servers (domain owners)

dig google.com
→ Final IP (what browser needs)